source-driven-development
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from external sources such as documentation URLs and web search results. This creates a surface for indirect prompt injection if a third-party website contains malicious instructions intended to manipulate the agent's behavior. However, this is a theoretical risk inherent to web-enabled agents and is mitigated here by the lack of any automated execution capabilities within the skill itself.
- Ingestion points: Local dependency files (
package.json) and external documentation websites retrieved via URL or web search. - Boundary markers: The skill does not define specific delimiters for external content but encourages verifying claims against authoritative sources.
- Capability inventory: The skill contains no scripts, executable tools, or filesystem-write operations. It is purely instructional.
- Sanitization: No explicit sanitization or filtering of external content is defined.
Audit Metadata